Exciting news! I'm hiring experienced vulnerability researchers @theZDI.
Do you love VR, sharing your work, and want to run categories at Pwn2Own? Come work with us (remotely).
Apply here: https://t.co/n7asBQcNOC
Feel free to DM me if you have any questions.
I made a write up diffing and triggering a use after free vulnerability in AFD.sys that was fixed in this month’s patch Tuesday:
https://t.co/Tq7aoSsP6D
Say hello to Eternal Tux🐧, a 0-click RCE exploit against the Linux kernel from KSMBD N-Days (CVE-2023-52440 & CVE-2023-4130)
https://t.co/Cbk9MBo91v
Cheers to @u1f383 for finding these CVEs + the OffensiveCon talk from gteissier & @laomaiweng for inspiration!
Today MSRC fixed two vulnerabilities I reported a couple months ago.
EoP in Windows Update service (affects only windows 11/10 with at least 2 drives)
https://t.co/YnCsk1934F
EoP in Microsoft PC Manager
https://t.co/ssudyvpgDS
PoC for CVE-2025-48799:
https://t.co/brRVf18DnY
From iframes and file reads to full RCE. 🔥
We found an HTML-to-PDF API allowing file reads and SSRF - then chained it into remote code execution via a Chromium 62 WebView exploit.
👉 Read the full write-up here: https://t.co/Qa5Beuuncr
CimFS: Crashing in memory, Finding SYSTEM! @cplearns2h4ck dug into Microsoft CimFS, found a sneaky 0-day, and guess what? The fix by Microsoft was just locking the door 🔐on unprivileged users. 😂
Dive into the adventure with us: https://t.co/7g30HpmFzG
(A new class of symlink attacks is mentioned below.)
According to Microsoft (MSRC), attacks involving symlinks stored on removable drives or in file system images (like VHDX) are not vulnerabilities.
If an unprivileged user manages to quickly replace a regular file... 1/7
Following our #38c3 talk about exploiting security software for privilege escalation, we're excited to kick off a new blog series! 🎊
Check out our first blog post on our journey to 💥 exploit five reputable security products to gain privileges via COM hijacking: https://t.co/5ne5FBggZl
ZDI Threat Hunting 2024: Highlights, Trends, & Challenges - @gothburz takes a look at the key achievements of our Threat Hunting team. He also looks at in-the-wild vuln trends and industry challenges we encountered in 2024 that will continue into 2025. https://t.co/4Tcvpne2Di